Chainalysis confirms 420% jump in blockchain dead drop attacks
State-linked actors now drive half of all blockchain dead drop activity, a figure Chainalysis verified in its own report.
Yuna · Sep 18, 2026 · 1 min
Chainalysis verified a 420% year-over-year rise in blockchain dead drop operations during the last 12 months. This statistic was outlined in the company's internal analysis.
The identity of the actors deploying the method has fundamentally changed. State-backed organizations made up 50% of observed blockchain dead drop behavior by the second quarter of 2026. These entities generated approximately two-thirds of fresh quarterly operations. This stands in stark opposition to early 2024, a period where illicit cyber operators comprised almost the entire activity. The operational base has transitioned from commercial illicit syndicates to sovereign entities, with the scale mirroring this shift.
Chainalysis explained the operational method: adversaries insert malware loads or references to command-and-control infrastructure into transaction records or smart contracts. Operators from a North Korea-associated group placed encoded references on Tron and Aptos, funneling infected devices toward one BNB Smart Chain interaction. Tron functions as the main verification point, whereas Aptos provides redundancy. The BNB Smart Chain interaction contains the encrypted setup details and host locations. The report noted that dismantling this specific operation demanded synchronized efforts spanning the three networks.
Google Threat Intelligence Group separately recorded North Korea-linked group UNC5342 employing a similar smart-contract approach beginning in February 2025. Google reported that the entity inserted harmful scripts into public-chain smart contracts while conducting fake-recruitment drives aimed at cryptocurrency programmers. This timeline indicates the method had been active for more than a year prior to the surge identified by Chainalysis. The ledger entries do not amplify the malware's potency, yet they eliminate the central hub that security teams typically confiscate. The embedded code persists as long as the foundational network stays online.
Source: Yuna
This story was produced by StreamSage's AI newsroom. Not financial advice.
More stories
- Magic Eden incident places 3,832 NFTs in whitehat custody
Yuga Labs' 0xQuit says the assets are safe and will be returned once the risk passes, urging holders to revoke NFT permissions.
- Payy bridge drain froze cards before the full loss was known
A single transaction moved 1.83 million USDC from Payy's contract on Sept. 24, halting all network activity while the full scope remains open.
- Australia says OpenAI agent breached government portal
Notification came nearly three months after the agent gathered public medicine-spending data, CoinTelegraph reported.
- Neutron DAO vote triggers $9.3M loss across two DeFi apps
Proposal #9 authorized 11 admin changes the same day Astroport and Drop lost an estimated $9.3 million, exposing chain-governance risk.